Saltar al contenido
Prolio

Privacy policy

Last updated: 2026-07-24

This is an informational translation. The Spanish version at /es/legal/privacy prevails in case of any discrepancy.

1. Data controller

  • Controller: Thorne Bridge Foundry, LLC
  • Legal form: LLC (Delaware Limited Liability Company, USA)
  • EIN (US Tax ID): 30-1491515
  • Registered address: 131 Continental Dr Suite 305, Newark, DE 19713 (USA)
  • Privacy email: thornebridgefoundry@gmail.com
  • No DPO appointed: Prolio does not carry out large-scale processing of special categories nor systematic monitoring under Art. 37 GDPR. This will be reviewed as the product grows.

2. Data we process

  • Pre-loaded professional listings (unclaimed): business or professional name, activity, city, office address, professional phone and email, website, licence or public-registry number where available, approximate coordinates and public ratings. Sources: each country's public records (professional bodies, commercial registries such as BORME, national and regional open data, OpenStreetMap, Google Places).
  • Claimed listings: the above plus account email, hashed password, voluntary data (description, photo, schedule, services) and the evidence supplied to claim the profile.
  • Lead submissions: name, email, optional phone, message.
  • Website visitors: strictly necessary technical data (IP, user-agent, event) and, only with consent, analytics metrics. Also: automatic technical error reports when the site fails (error message, page, browser, IP), and, if you arrive from a campaign, first-party attribution parameters (utm_*) stored in our own cookies β€” see the Cookie policy.

3. Minimisation and pre-claim visibility reduction

We apply Art. 5.1.c GDPR data minimisation. For unclaimed listings: (a) only professional data strictly necessary for identification; (b) email and phone are shown only after an explicit "Show contact" click to deter automated scraping; (c) we do not publish personal tax IDs of self-employed individuals; (d) we only publish office addresses, never residential; (e) listings are removed immediately when the subject requests opt-out.

4. Purposes and legal basis (Art. 6 GDPR)

  • Running the public professional directory (unclaimed listings) β€” legitimate interest (Art. 6.1.f). A legitimate-interest assessment is documented (see section 5).
  • Routing lead requests to professionals β€” performance of a service (Art. 6.1.b) and legitimate interest of the receiving professional.
  • Authentication, claim, and profile management by the professional β€” contract (Art. 6.1.b).
  • Abuse prevention and security β€” legitimate interest (Art. 6.1.f).
  • Error monitoring and technical diagnostics (Sentry) β€” legitimate interest (Art. 6.1.f). No cookies, never used for advertising.
  • First-party campaign attribution (our own utm_* cookies) β€” legitimate interest (Art. 6.1.f); no third-party sharing.
  • Service and software improvement using internal AI tooling (see section 12) β€” legitimate interest (Art. 6.1.f).
  • Traffic and product analytics (GA4, PostHog) β€” explicit consent (Art. 6.1.a), via the cookie banner.
  • Legal obligations (invoicing, lawful requests) β€” legal obligation (Art. 6.1.c).

5. Legitimate-interest assessment (LIA)

For pre-loaded professional listings sourced from public records, we have documented the following three-step LIA, available to the AEPD on request:

  • Purpose: provide a reliable directory of regulated professionals in the countries where Prolio operates (Spain, France, the USA, Canada, Mexico and Colombia), reduce information asymmetry for consumers, and give visibility to self-employed and SMEs without SEO resources. Lawful, real and specific interest.
  • Necessity: initial critical mass requires pre-loading already-public data; without this nucleus the service would not be useful to either side.
  • Balancing test: data is professional (not private-sphere), sourced publicly, minimal, and subjects have robust objection/erasure/one-click opt-out mechanisms. No automated decisions with legal effects, no sensitive profiling.
  • Safeguards: hidden-behind-click contact, no ads or remarketing, permanent opt-out link in every outbound email, public rights form, one-month statutory response commitment, definitive erasure on request (not just unpublish).

6. Retention

  • Unclaimed listings: while the data remains relevant or until objection/erasure β€” immediate unpublication, full deletion within 30 days.
  • Claimed listings: duration of the relationship plus applicable limitation periods (up to 6 years for tax/commercial records).
  • Leads: 24 months.
  • Opt-out tokens: 90 days.
  • Cookie consent logs: 24 months (AEPD evidence).
  • Technical and security logs: 12 months.
  • Technical error reports (Sentry): 90 days (provider's standard retention).
  • Attribution cookies (utm_*): 30 days.
  • Billing data: 6 years.

7. Processors

  • Supabase (DB + auth) β€” Frankfurt / Ireland (EEA).
  • Vercel Inc. (hosting) β€” USA, SCCs.
  • Google LLC (Places API) β€” USA, SCCs.
  • Google Analytics 4 (consent-gated) β€” USA, SCCs.
  • PostHog Inc. at us.i.posthog.com (consent-gated) β€” USA, SCCs.
  • Functional Software, Inc. ("Sentry") β€” error monitoring β€” USA, SCCs. Receives error reports with IP and user-agent; sets no cookies.
  • Stripe Payments Europe Ltd. (plan payments) β€” Ireland, USA sub-processor under SCCs.
  • Resend, Inc. (transactional email: verification, account notices, professional outreach with opt-out link) β€” USA, SCCs.
  • Anthropic PBC (internal AI tooling for quality audits, error detection and software development; see section 12) β€” USA, SCCs; no right to train models on our data.

8. International transfers

Several processors sit outside the EEA (mostly USA). We rely on EU Standard Contractual Clauses (June 2021) and, where applicable, the EU-US Data Privacy Framework for certified vendors, plus TLS in transit, encryption at rest and EU region choice where available.

9. Your rights

You have the right to access, rectification, erasure, objection, restriction, portability, and withdrawal of consent at any time β€” without affecting the lawfulness of prior processing. Exercise via thornebridgefoundry@gmail.com or /en/ejercer-derechos. We reply within one month (extendable by two further months in complex cases, with notice).

Identity verification: to prevent impersonation we may ask for reasonable proof of identity when the request involves data not already associated with the sender email. The request will be proportionate (e.g. confirmation from the published professional email).

You may lodge a complaint with the Spanish Data Protection Agency (AEPD, C/ Jorge Juan 6, 28001 Madrid; www.aepd.es). If you live outside Spain, you may also contact your local authority (see section 13).

10. Security and breach notification

We apply reasonable and proportionate technical and organisational measures (Art. 32 GDPR): role-based access, TLS 1.2+, encryption at rest by the DB provider, host-managed secrets, least-privilege API keys, audit logs, updated dependencies.

Breach notification: AEPD within 72 hours (Art. 33) and affected subjects when risk is high (Art. 34).

11. Automated decisions

We do not take decisions based solely on automated processing that produce legal effects or significantly affect subjects. Directory rankings are informational and based on aggregate signals. The AI tooling described in section 12 likewise takes no decisions with legal effects on data subjects.

12. Use of artificial intelligence

We use AI tooling (Anthropic "Claude" models) internally to maintain and improve the service: automated quality and SEO audits of the public pages, error detection and diagnosis, and development of the software itself. This tooling mainly operates on information already published in the directory and on technical or aggregated usage data; where it exceptionally touches other data (e.g. while diagnosing a specific error), the same confidentiality safeguards apply and the AI provider acts as a processor under a DPA and SCCs.

We do not use personal data to train AI models, and our AI providers have no right to train their models on data processed on Prolio's behalf. AI-assisted software changes are reviewed by a human before release. Listing descriptions are generated from deterministic templates over the listing's own public data, not by generative AI. We also block third-party AI-training crawlers in robots.txt.

13. Territorial scope and local rights

We apply the GDPR standard described here across all our markets. Depending on where you live, the following frameworks and authorities also apply:

  • Spain β€” GDPR and LOPDGDD; authority: AEPD (www.aepd.es).
  • France β€” GDPR; authority: CNIL (www.cnil.fr), including post-mortem data directives under the French Data Protection Act.
  • United States β€” state privacy laws (incl. California CCPA/CPRA): rights to know, access, correct and delete, and to non-discrimination. Prolio does not "sell" or "share" personal information within the meaning of the CPRA (no behavioural advertising, no commercial disclosure to third parties). Requests: thornebridgefoundry@gmail.com or the /ejercer-derechos form.
  • Canada β€” PIPEDA and, in Quebec, Law 25: access, correction and consent withdrawal; authorities: OPC and, in Quebec, the CAI.
  • Mexico β€” LFPDPPP: ARCO rights (access, rectification, cancellation, objection) via the same channels; authority: INAI.
  • Colombia β€” Law 1581 of 2012 (habeas data): rights to know, update, rectify and delete, and to revoke authorisation; authority: SIC.

14. Minors

Prolio is not directed at under-14s. We remove any such data on discovery.

15. Changes

We may update this policy. Material changes re-trigger consent for non-strictly-necessary cookies.